检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-F89H-2FJH-2R9Q CVE-2026-44471 | gix-fs: Symlink prefix-reuse allows worktree escape during checkout | 高危 | crates.iogix-fs | 已审查 | 2026-05-07 08:01 | 2026-05-15 04:43 |
| GHSA-9VQF-7F2P-GF9V CVE-2026-44456 | Hono: bodyLimit() can be bypassed for chunked / unknown-length requests |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmhono |
| 已审查 |
| 2026-05-07 07:50 |
| 2026-05-15 04:32 |
| GHSA-69XW-7HCM-H432 CVE-2026-44455 | hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection | 中危 | npmhono | 已审查 | 2026-05-07 07:49 | 2026-05-15 04:31 |
| GHSA-QXRW-F6FH-34R7 | Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users | 中危 | crates.iolemmy_api | 已审查 | 2026-05-07 07:49 | 2026-05-07 07:49 |
| GHSA-687H-XW6F-Q2QW CVE-2026-44439 | Playwright Capture permits access to local files and internal network resources during page capture | 中危 | PyPIPlaywrightCapture | 已审查 | 2026-05-07 07:43 | 2026-06-09 09:59 |
| GHSA-69XR-M8H6-H664 CVE-2026-44437 | Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix | 中危 | npm@angular/ssr | 已审查 | 2026-05-07 07:42 | 2026-05-15 04:43 |
| GHSA-QCXQ-75WR-5CM8 | ldap3_proto has LDAP Filter stack exhaustion | 高危 | crates.ioldap3_proto | 已审查 | 2026-05-07 07:39 | 2026-08-15 03:22 |
| GHSA-84JC-3HJ2-HWC7 | kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input | 中危 | crates.iokanidmd_lib | 已审查 | 2026-05-07 07:39 | 2026-05-07 07:39 |
| GHSA-R5FR-9GMV-JGGH CVE-2026-46689 | scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion | 高危 | crates.iokanidm_proto+1 | 已审查 | 2026-05-07 07:38 | 2026-06-29 23:30 |
| GHSA-53HJ-R94P-8C8F | Kanidm has non-constant-time comparison of OAuth2 client_secret | 低危 | crates.iokanidm | 已审查 | 2026-05-07 07:37 | 2026-05-07 07:37 |
| GHSA-GPXG-FX2G-QXJ2 | Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery | 中危 | crates.iokanidm | 已审查 | 2026-05-07 07:34 | 2026-05-07 07:34 |
| GHSA-22W3-693W-X895 | webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed | 低危 | crates.iowebauthn-authenticator-rs+1 | 已审查 | 2026-05-07 07:31 | 2026-05-07 07:31 |
| GHSA-47R2-V3X6-WFF9 CVE-2026-44425 | ShellHub has crash-DoS via field injection in filter and sort-by parameters | 中危 | Gogithub.com/shellhub-io/shellhub | 已审查 | 2026-05-07 07:28 | 2026-05-15 04:43 |
| GHSA-CQMH-PCGR-Q42F | @axonflow/openclaw fix introduces plugin cache and credential-file permission hardening | 中危 | npm@axonflow/openclaw | 已审查 | 2026-05-07 07:23 | 2026-05-07 07:23 |
| GHSA-9W9C-9W8M-W89Q CVE-2026-44423 | ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data | 中危 | Gogithub.com/shellhub-io/shellhub | 已审查 | 2026-05-07 07:22 | 2026-07-21 21:57 |
| GHSA-J72X-XFWG-783F CVE-2026-44424 | ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace | 中危 | Gogithub.com/shellhub-io/shellhub | 已审查 | 2026-05-07 07:19 | 2026-05-15 04:43 |
| GHSA-248H-974Q-XRC2 | axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification | 中危 | Mavencom.getaxonflow:axonflow-sdk | 已审查 | 2026-05-07 07:16 | 2026-09-03 00:03 |
| GHSA-MPH8-9V29-PM42 | axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification | 中危 | npm@axonflow/sdk | 已审查 | 2026-05-07 07:16 | 2026-05-07 07:16 |
| GHSA-MHC4-QQ83-FMRR | axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification | 中危 | Gogithub.com/getaxonflow/axonflow-sdk-go/v5 | 已审查 | 2026-05-07 07:15 | 2026-05-07 07:15 |
| GHSA-7F4H-6264-89FR | axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification | 中危 | PyPIaxonflow | 已审查 | 2026-05-07 07:14 | 2026-05-07 07:14 |
| GHSA-9H64-2846-7X7F | Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening | 严重 | Gogithub.com/getaxonflow/axonflow | 已审查 | 2026-05-07 07:13 | 2026-05-07 07:13 |
| GHSA-RWM7-X88C-3G2P CVE-2026-42577 | Netty epoll transport denial of service via RST on half-closed TCP connection | 高危 | Mavenio.netty:netty-transport-classes-epoll | 已审查 | 2026-05-07 07:10 | 2026-07-25 03:05 |
| GHSA-MGX6-5CF9-RR43 CVE-2026-0897 | Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor) | 高危 | PyPIkeras | 已审查 | 2026-05-07 07:09 | 2026-06-09 02:34 |
| GHSA-2CWQ-PWFR-WCW3 CVE-2026-44375 | Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException | 高危 | NuGetNerdbank.MessagePack | 已审查 | 2026-05-07 07:05 | 2026-05-15 04:49 |
| GHSA-P7G9-RP3G-MGFG CVE-2026-44374 | Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks | 中危 | npm@backstage/plugin-catalog-backend-module-unprocessed+2 | 已审查 | 2026-05-07 07:04 | 2026-05-15 04:49 |